Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware

The Hacker NewsNotepad++ has released a security fix to plug gaps that were exploited by an advanced threat actor from China to hijack the software update mechanism to selectively deliver malware to targets of interest.
The version 8.9.2 update incorporates what maintainer Don Ho calls a “double lock” design that aims to make the update process “robust and effectively unexploitable.” This includes verification​

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *